Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 7.8
CVE-2016-3940

The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices allows attackers to gain privileges via a crafted a…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3939

drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices…

Mitigation only
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3938

drivers/video/msm/mdss/mdss_mdp_overlay.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One d…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3933

mediaserver in Android before 2016-10-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal b…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3932

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTe…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3931

drivers/misc/qseecom.c in the Qualcomm QSEE Communicator driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices …

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3930

The NVIDIA MMC test driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka interna…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3928

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 300193…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3922

libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attack…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3921

libsysutils/src/FrameworkListener.cpp in Framework Listener in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-0…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3917

The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication …

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3915

camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3913

media/libmediaplayerservice/MediaPlayerService.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 201…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3912

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allow attack…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3911

core/java/android/os/Process.java in Zygote in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 befor…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3910

services/soundtrigger/SoundTriggerHwService.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 befo…

Patch available
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3909

The SoftMPEG4 component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, …

Patch available
Fix from $1,950 2016-10-10
Android MEDIUM 5.5
CVE-2016-3908

The Lock Settings Service in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to remove a device's PIN or password, and conse…

Patch available
Fix from $1,600 2016-10-10
Android HIGH 7.8
CVE-2016-3905

CORE/HDD/src/wlan_hdd_main.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a …

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3903

drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm camera driver in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6,…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3900

cmds/servicemanager/service_manager.c in ServiceManager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016…

Patch available
Fix from $1,950 2016-10-10
Linux Kernel HIGH 7.3
CVE-2015-8955

arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (…

Fix: 3.16.39 / 3.18.54+
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2015-8951

Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus …

Fix: after 7.0
Fix from $1,950 2016-10-10
Linux Kernel HIGH 7.4
CVE-2016-3699

The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local us…

Patch available
Fix from $1,950 2016-10-07
Ios Xr HIGH 7.8
CVE-2016-6428

Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.

Mitigation only
Fix from $1,950 2016-10-06
Sterling Secure Proxy MEDIUM 5.9
CVE-2016-6025

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to o…

Mitigation only
Fix from $1,600 2016-10-06
Nx Os HIGH 8.0
CVE-2015-0721

Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allo…

Mitigation only
Fix from $1,950 2016-10-06
Netweaver CRITICAL 9.1
CVE-2016-7435

The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.…

Mitigation only
Fix from $2,300 2016-10-05
Firesight System Software MEDIUM 6.5
CVE-2016-6420

Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks …

Mitigation only
Fix from $1,600 2016-10-05
Embedded Pc Images CRITICAL 9.1
CVE-2014-5415

Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain acc…

Mitigation only
Fix from $2,300 2016-10-05